<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic UDP Packet attack - IPS detection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/udp-packet-attack-ips-detection/m-p/1851136#M922207</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been having logs for Access-lists configured on an interface on my 6509. Can anyone advise please if I am understanding it correct that IP10.61.64.202 is responsible for bursting attacks on udp port. Many thanks in advance for providing insight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 20 13:58:15.709 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(50575) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61488) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61482) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61487) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:45.865 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(59357) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:59:15.981 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55403) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:59:46.193 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(56614) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:00:23.962 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:00:23.962 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:00:52.610 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58196) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:05.194 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:22.838 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55329) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 7 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:02:26.498 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(62934) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:02:44.487 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52203) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:03:02.579 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(62834) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:03:24.055 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:04:14.203 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.87(63295) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:04:24.087 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:05:24.116 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55344) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58203) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55343) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55347) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55338) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58202) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:22.433 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58567) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:24.213 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(54781) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:52.513 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(56322) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:15.821 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(63011) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:33.421 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.241(138) -&amp;gt; 10.54.131.255(138), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:46.077 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(63027) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:10:05.309 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:10:24.278 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:10:24.278 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:10:53.738 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(50736) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 11 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:12:24.338 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:12:42.370 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49958) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:13:04.623 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:13:24.375 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:14:14.527 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.87(63844) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:14:24.407 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:15:24.436 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58846) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(60644) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(64297) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 110 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49355) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(57310) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55738) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55936) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:08.149 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52177) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49959) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49964) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49965) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:53.249 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52185) -&amp;gt; 10.54.131.255(7), 1 packet&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Feb 20 13:58:15.709 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(50575) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61488) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61482) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61487) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:45.865 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(59357) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:59:15.981 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55403) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:59:46.193 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(56614) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:00:23.962 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:00:23.962 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:00:52.610 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58196) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:05.194 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:22.838 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55329) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 7 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:02:26.498 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(62934) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:02:44.487 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52203) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:03:02.579 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(62834) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:03:24.055 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:04:14.203 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.87(63295) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:04:24.087 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:05:24.116 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55344) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58203) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55343) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55347) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55338) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58202) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:22.433 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58567) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:24.213 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(54781) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:52.513 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(56322) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:15.821 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(63011) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:33.421 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.241(138) -&amp;gt; 10.54.131.255(138), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:46.077 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(63027) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:10:05.309 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:10:24.278 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:10:24.278 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:10:53.738 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(50736) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 11 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:12:24.338 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:12:42.370 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49958) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:13:04.623 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:13:24.375 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:14:14.527 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.87(63844) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:14:24.407 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:15:24.436 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58846) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(60644) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(64297) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 110 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49355) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(57310) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55738) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55936) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:08.149 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52177) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49959) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49964) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49965) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:53.249 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52185) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 12:34:10 GMT</pubDate>
    <dc:creator>jpugliese</dc:creator>
    <dc:date>2020-02-21T12:34:10Z</dc:date>
    <item>
      <title>UDP Packet attack - IPS detection</title>
      <link>https://community.cisco.com/t5/network-security/udp-packet-attack-ips-detection/m-p/1851136#M922207</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been having logs for Access-lists configured on an interface on my 6509. Can anyone advise please if I am understanding it correct that IP10.61.64.202 is responsible for bursting attacks on udp port. Many thanks in advance for providing insight.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Feb 20 13:58:15.709 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(50575) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61488) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61482) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61487) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:45.865 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(59357) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:59:15.981 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55403) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:59:46.193 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(56614) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:00:23.962 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:00:23.962 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:00:52.610 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58196) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:05.194 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:22.838 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55329) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 7 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:02:26.498 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(62934) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:02:44.487 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52203) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:03:02.579 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(62834) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:03:24.055 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:04:14.203 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.87(63295) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:04:24.087 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:05:24.116 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55344) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58203) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55343) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55347) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55338) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58202) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:22.433 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58567) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:24.213 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(54781) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:52.513 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(56322) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:15.821 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(63011) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:33.421 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.241(138) -&amp;gt; 10.54.131.255(138), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:46.077 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(63027) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:10:05.309 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:10:24.278 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:10:24.278 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:10:53.738 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(50736) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 11 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:12:24.338 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:12:42.370 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49958) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:13:04.623 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:13:24.375 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:14:14.527 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.87(63844) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:14:24.407 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:15:24.436 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58846) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(60644) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(64297) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 110 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49355) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(57310) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55738) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55936) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:08.149 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52177) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49959) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49964) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49965) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:53.249 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52185) -&amp;gt; 10.54.131.255(7), 1 packet&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Feb 20 13:58:15.709 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(50575) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61488) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61482) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:23.901 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(61487) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:58:45.865 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(59357) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:59:15.981 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55403) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 13:59:46.193 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(56614) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:00:23.962 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:00:23.962 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:00:52.610 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58196) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:05.194 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:22.838 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55329) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 7 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:01:23.990 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:02:26.498 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(62934) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:02:44.487 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52203) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:03:02.579 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(62834) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:03:24.055 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:04:14.203 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.87(63295) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:04:24.087 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:05:24.116 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55344) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58203) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55343) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55347) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55338) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:06:24.152 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58202) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:22.433 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58567) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:24.213 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(54781) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:08:52.513 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(56322) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:15.821 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(63011) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:33.421 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.241(138) -&amp;gt; 10.54.131.255(138), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:09:46.077 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(63027) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:10:05.309 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:10:24.278 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:10:24.278 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:10:53.738 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(50736) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 11 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:11:24.310 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 111 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:12:24.338 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:12:42.370 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49958) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:13:04.623 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:13:24.375 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:14:14.527 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.87(63844) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:14:24.407 AEDT: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:15:24.436 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied igmp 10.54.131.253 -&amp;gt; 224.0.0.1, 5 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(58846) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGRP: list VC-COLO-OUTBOUND denied pim 10.54.131.253 -&amp;gt; 224.0.0.13, 10 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(60644) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(64297) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:16:24.468 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-OUTBOUND denied udp 10.54.131.253(1985) -&amp;gt; 224.0.0.2(1985), 110 packets&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49355) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(57310) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55738) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:17:24.500 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(55936) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:08.149 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52177) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49959) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGDP: list VC-COLO-INBOUND denied icmp 157.128.202.2 -&amp;gt; 10.54.131.253 (8/0), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49964) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:24.533 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(49965) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;&lt;P&gt;Feb 20 14:18:53.249 AEDT: %SEC-6-IPACCESSLOGP: list VC-COLO-INBOUND denied udp 10.61.64.202(52185) -&amp;gt; 10.54.131.255(7), 1 packet&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/udp-packet-attack-ips-detection/m-p/1851136#M922207</guid>
      <dc:creator>jpugliese</dc:creator>
      <dc:date>2020-02-21T12:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: UDP Packet attack - IPS detection</title>
      <link>https://community.cisco.com/t5/network-security/udp-packet-attack-ips-detection/m-p/1851137#M922208</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="font-family: 'trebuchet ms', geneva; font-size: 12pt;"&gt;So, you can use &lt;A href="http://ospfmon.com" rel="nofollow"&gt;http://ospfmon.com&lt;/A&gt; to detect any attacks on your system&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2012 09:58:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/udp-packet-attack-ips-detection/m-p/1851137#M922208</guid>
      <dc:creator>Miroslav Berkov</dc:creator>
      <dc:date>2012-03-01T09:58:53Z</dc:date>
    </item>
  </channel>
</rss>

